|
|
| |
|
| |
hplip: symlink attack
| Package(s): | hplip |
CVE #(s): | CVE-2011-2722
|
| Created: | September 12, 2011 |
Updated: | February 21, 2013 |
| Description: |
From the Red Hat bugzilla:
A temporary file handling flaw was reported in prnt/hpijs/hpcupsfax.cpp,
the hplip HP CUPS filter. Because a predictable temporary filename is used
(/tmp/hpcupsfax.out), an attacker could use a symlink attack to overwrite an
arbitrary file with the privileges of the process running the HP CUPS fax
filter. |
| Alerts: |
|
( Log in to post comments)
|
|
|